Is cold calling legal in Spain? What the law actually requires in 2026

Filipp Contell Vashchenko· Founder of NoBuSales 13 min readLegal
In this article

Read this part first, and we mean it: this is general information, not legal advice. Everything below is sourced to Spanish primary law — the Boletín Oficial del Estado — or to a published document of the Spanish data protection authority, the AEPD, current as at July 2026. Have your case reviewed by a Spanish data protection lawyer before you launch: where your data comes from, who you call and what you offer them all change the answer.

The honest answer to the question in the title is neither yes nor no. Cold calling Spanish businesses is lawful under specific, documented conditions — and one central piece of the framework, the scope of article 19 of the Spanish data protection act, is not settled, with the AEPD itself taking different positions in different documents. Anyone who tells you this is closed, in either direction, is selling comfort rather than information.

In short: Since 29 June 2023, article 66.1.b) of Spain's Ley 11/2022 requires prior consent — or another lawful basis under article 6.1 GDPR — before a commercial call. The AEPD's Circular 1/2023 is binding law (art. 55.3 LOPDGDD), applies to every sector, and demands a documented balancing test before you dial, plus a Robinson List check with no B2B exception. Fines reach €2,000,000. Whether article 19 LOPDGDD covers selling to a professional, as opposed to hiring one, remains unresolved by the AEPD and untested in court.

What changed in Spain on 29 June 2023?

The default flipped. Article 66.1.b) of Ley 11/2022, the Spanish General Telecommunications Act, gives end users the right not to receive unwanted commercial calls, unless the user has given prior consent or the call rests on another lawful basis under article 6.1 GDPR. The Act was published in June 2022, but its sixth final provision deferred this right by a year, so it took effect on 29 June 2023.

The AEPD's legal service put the shift precisely in report 0052/2023: Spain moved from presuming the caller's legitimate interest, with the individual holding only a right to object, to a recognised right not to receive unwanted commercial calls. The right carries a matching obligation on the caller: do not make the call unless you can demonstrate one of the two exceptions — which, being exceptions, are to be read restrictively. If your operation assumes you may call until someone tells you to stop, that stopped being true in Spain three years ago.

A stricter tier sits alongside it: article 66.1.a) requires prior consent, with no alternative basis at all, for automated calls without human intervention and for faxes. A dialler that plays a recording has no legitimate-interest door to open. A human conversation does.

Is the AEPD's Circular 1/2023 guidance or law?

It is law: article 55.3 LOPDGDD makes circulars binding once published in the BOE, and Circular 1/2023 was published on 28 June 2023.

Two features surprise teams arriving from outside Spain. First, article 1.1 applies it to any controller making commercial calls, expressly "regardless of the sector" — this is not telecoms-industry regulation, and it is not drafted as consumer-only. Second, the AEPD rules out the contractual basis of article 6.1.b) GDPR here, leaving two doors: consent (6.1.a) and legitimate interest (6.1.f). In cold prospecting the first almost never exists, so the weight falls on the second — and per report 0052/2023, consent cannot be collected during the call it is meant to authorise. It has to exist before you dial.

Can legitimate interest cover cold calls into Spain?

Yes, but the work happens before the first dial, not after the first complaint. Article 3 of the Circular requires the controller to carry out the balancing of competing rights and interests before processing begins, and to justify it to the AEPD on request.

Then comes the uncomfortable part. The Circular presumes lawfulness — rebuttably — in one narrow scenario: a prior contractual relationship, data obtained lawfully, and communications about products or services of your own company that are similar to those originally contracted. It does not extend to passing data to other companies in your group. And the AEPD states it will not presume a "reasonable expectation" on the recipient's side where there is no current contractual relationship, request or interaction by that person in the last year.

Read that again: it is the literal definition of a cold call. No presumption does not mean no calling — it means the legitimate interest is yours to build and defend, campaign by campaign. Report 0052/2023 warns it cannot be invoked generically, because an unbounded reading would strip the 2023 reform of its practical effect.

One escape route is closed outright: the AEPD treats a telephone number, on its own, as personal data. "We are calling a number, not a person" is not an argument in Spain.

Doesn't article 19 put B2B outside all of this?

This is where foreign teams pin their hopes, and where the ground is least firm. Article 19.1 LOPDGDD presumes that processing the contact details — and where applicable the role — of natural persons who provide services to a legal entity is covered by legitimate interest under article 6.1.f) GDPR, subject to two cumulative conditions: only the data necessary to locate them professionally, and the sole purpose of maintaining a relationship with the entity they work for. Article 19.2 extends the presumption to sole traders and liberal professionals, but only where they are dealt with in that capacity and not as individuals. Article 5 of the Circular points straight at article 19: it is the normative anchor of B2B outbound in Spain.

The unresolved question is what you may use the presumption for.

  • The broad reading. The preamble to the Circular, report 0052/2023 and the AEPD's public FAQ 0506 all indicate it operates where the contact concerns the offer of products and services related to the person's professional or business activity. On this reading, calling an operations director about a solution in their field is covered.
  • The narrow reading. In resolution PS/00084/2024 (file EXP202312711, ADVERBIS SPAIN, S.L.), the AEPD suggested the case would have been closed had the call been made to engage the complainant's professional services, and criticised the company for "sheltering behind article 19" to make a sales call without consent. On this reading, article 19 lets you call a lawyer to hire the lawyer, not to sell them your software. The fine was €5,000 for breaching article 66.1.b).

That gap is exactly the ground on which all B2B prospecting operates, and it has not been closed. As at July 2026 we are not aware of any ruling of the Audiencia Nacional or the Tribunal Supremo interpreting article 66.1.b) in B2B prospecting — only administrative decisions of the AEPD.

A second grey zone is worth naming rather than hiding: calling the direct line of an identified professional is processing of personal data and sits inside everything above, while calling a generic corporate switchboard with no identifiable person behind it has no settled doctrine. Not a safe harbour — an open question.

Do we have to check the Robinson List for business calls?

Yes, and this is the most common mistake in the questions we get from abroad. Article 23.4 LOPDGDD requires anyone intending to carry out direct marketing to consult advertising exclusion systems beforehand and remove those who have objected. There is no B2B carve-out; the only exemption is holding that person's consent. Article 4 of the Circular makes the check express for commercial calls.

According to the AEPD, Spain has a single common exclusion file: the Lista Robinson, run independently by Adigital, with registration effective three months after sign-up. Sole traders and liberal professionals do register — and the Spanish company population is overwhelmingly small-scale: 54.4% of active companies had no salaried employees at all at 1 January 2025, and 81.6% had two or fewer (INE, DIRCE). In the ADVERBIS decision the fact that the person called appeared on the list was decisive, even though they advertised their services publicly. Note too that article 23.1 LOPDGDD was amended by Ley 10/2025, in force since 28 December 2025, adding "preference services" that let individuals restrict commercial communications to specified companies. Checklists written before 2026 are out of date.

What has to happen on every single call?

RequirementSourceWhat it means operationally
Balancing test documented before the campaignArt. 3 Circular 1/2023A dated document, written before the first dial, explaining why your legitimate interest is not overridden by the rights and freedoms of the person called (art. 6.1.f GDPR)
Exclusion systems consultedArt. 4 Circular + art. 23.4 LOPDGDDA logged Robinson List screening before the list is worked
Identify, declare, informArt. 6.a) Circular 1/2023At the start of every call: who the company is, that the call is commercial, and that the recipient can withdraw consent or object. No pretext openers
Honour any refusal immediatelyArt. 6.b) Circular 1/2023An unequivocal refusal counts as an objection and must be acted on at once — a suppression list that is genuinely respected
Call recordingArt. 6.c) Circular 1/2023Contemplated as a means of demonstrating compliance
No mobile numberingArt. 9.1 Orden TDF/149/2025Mobile ranges may not be used for unsolicited commercial calls; the 800 and 900 ranges are attributed to that purpose (art. 10)

That last rule catches almost every foreign operation, because most outbound stacks use whatever numbering the provider hands out. It is the cheapest item here to fix and the easiest to prove against you.

Why does this surprise US and UK sales teams?

Because the shape of the obligation differs, not merely the detail. Most playbooks arriving in Spain assume a suppression-first model: screen against a do-not-call register, dial, stop when asked. Spain has the register step, but it sits on top of a prior question that must be answered in writing before the campaign exists: what is our lawful basis, and why does it survive a balancing test? The register is a filter, not the permission. Three imported assumptions to drop:

  • "It's a business number, so it's out of scope." Not to the AEPD, and the Circular applies regardless of sector.
  • "We'll get permission at the top of the call." Asking for ninety seconds is excellent selling. Legally it fixes nothing: consent must precede the dial.
  • "Do-not-call registers are a consumer thing." The Robinson List obligation has no B2B exception, and sole traders register.

What about cold email — is it easier?

It is harder, not easier, and NoBuSales does not do it. Our channel is the telephone.

Article 21.1 LSSI prohibits commercial email that has not been previously requested or expressly authorised. The article 21.2 exception is narrow: a prior contractual relationship, data obtained lawfully from the recipient themselves, products or services of your own company similar to those contracted, and a simple, free opt-out in every message. Article 20.1 adds that the message must be clearly identifiable as commercial, as must the party on whose behalf it goes out. And the LSSI does not exclude B2B: its definition of recipient covers legal persons and anyone using the service "whether or not for professional purposes".

So buying a list and mailing it is not on a softer footing because the addresses end in a company domain. That contrast — a call you can ground in legitimate interest, an email you generally cannot — is why our cold calling operation is built on the phone.

What does getting it wrong cost?

FrameworkTierAmount
General Telecommunications ActSerious (art. 107.30)Up to €2,000,000 (art. 109.1.c)
General Telecommunications ActMinor (art. 108.11)Up to €100,000
LSSISerious€30,001 – €150,000
LSSIMinorUp to €30,000
GDPRArt. 83.5Up to €20m or 4% of global annual turnover
GDPRArt. 83.4Up to €10m or 2% of global annual turnover

The competent authority for article 66 breaches is the AEPD, not the telecoms regulator (art. 114.1.b LGTel). The ceiling is €2m, but the only amount we can cite with the decision in front of us is the €5,000 imposed in PS/00084/2024 — the one file we have located in which the AEPD engages expressly with the B2B argument. A single case does not establish a typical figure, and the AEPD does not break commercial calls out as a category in its published complaint figures either. What is certain is that the cost is never only the fine: it is the complaint, the file, the management time, and the brand damage in front of an account you wanted as a customer.

So can a foreign company run cold calling into Spain?

Yes, if it is built properly — and the build is mostly documentation, not restraint. The compliant version of this work is not "call less": it is a narrower account list, a written basis for calling it, and an opening that says who you are and why you are calling. All of which points the same way as good outbound anyway, because a tight ICP is far easier to defend than a broad one: you can explain why this role, in this kind of company, would reasonably expect this offer.

That is why our method starts with the account list, not the dialler. In Spain, the only market we work in, it produces a monthly funnel of 100 ICP accounts worked → all 100 contacted → 35 conversations with the decision-maker → 16 meetings booked → 13 attended → 9 opportunities, with 20–40% of accounts worked reaching a conversation with the decision-maker after several attempts spread over a month (normally around six, with no hard cap), an 83% show rate and a sales cycle of roughly three months, across an operation of more than 300 Mid Market and Enterprise accounts. Accounts that never answer are parked and worked again a few months later, rather than written off.

The usual next steps are a dedicated outsourced SDR as the operating model, appointment setting if you already know who you want to meet, or market validation calls to test whether Spanish buyers respond before you hire locally. Engagements run on six-month plans with a monthly target and a penalty-free exit if we miss it three months running, from €1,500 per month. There is more on our English overview, or request a free diagnostic to have the numbers run against your own ICP.

Second warning, as serious as the first: this article is general information and does not constitute legal advice. The framework is moving — Ley 10/2025 amended article 23.1 LOPDGDD in December 2025 and Orden TDF/149/2025 changed the numbering rules — and every operation has particulars we cannot cover here. Have a Spanish data protection lawyer review your case before you launch anything.

Frequently asked questions

Neither a plain yes nor a plain no, and anyone who gives you one is selling comfort rather than information. Calling a business in Spain is lawful under specific, documented conditions. Since 29 June 2023, article 66.1.b) of Ley 11/2022 gives end users the right not to receive unwanted commercial calls unless there is prior consent or another lawful basis under article 6.1 GDPR. In cold prospecting that means legitimate interest, and the balancing test behind it has to exist in writing before you dial. One central piece of the framework, the scope of article 19 LOPDGDD, is genuinely unsettled: the AEPD has taken different positions in different documents. This is general information, not legal advice; have a Spanish data protection lawyer review your case.